EASM Discovery

Also known as:EASM

EASM Discovery: Identification of an organization’s publicly accessible systems, services, and exposures. The term is relevant for the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.

How it works and where it fits

EASM Discovery denotes a technical component or operating environment with its own trust boundaries, identities, interfaces, and dependencies. Security is determined not only by the product, but by architecture, configuration, and the way data and privileges cross component boundaries. Management planes and production processing should be considered separately.

Practical security relevance

Secure operation depends on complete inventory, hardened baselines, least privilege, patchability, and centralized telemetry. Changes should be reproducible and reviewable. Exposed interfaces, default access, secrets, and supply-chain dependencies need particular attention; isolation, backup, and recovery must also be exercised in realistic conditions.

  • External Attack Surface ManagementExternal Attack Surface ManagementIdentifies and monitors assets and risks accessible from the Internet.: Identifies and monitors assets and risks accessible from the Internet.
  • Asset ManagementAsset ManagementInventories and manages hardware, software, cloud resources, and their security status.: Inventories and manages hardware, software, cloud resources, and their security status.
  • Attack SurfaceAttack SurfaceThe totality of all potentially vulnerable entry points of a system.: The totality of all potentially vulnerable entry points of a system.
  • CAASMCAASMPlatform approach for the inventory, correlation, and assessment of security-relevant assets.: Platform approach for the inventory, correlation, and assessment of security-relevant assets.